What a provider holds
A provider is a name plus values for the method’s “Set on provider” fields - the fields the connector author marked to be filled on the provider rather than on each connection. Each value is addressed by its connection slot:Key1throughKey10- connector-specific fields (for an OAuth app, usually the client id and client secret)ApiUser/ApiPassword- API credentialsBaseUrl- a vendor or custom endpoint URL
engini connections auth-providers sources lists them.
There is no clientId / clientSecret property: the API rejects both with 400 INVALID_AUTH_PROVIDER. Where a connector lets you bring your own OAuth client, it marks those fields “Set on provider” and you send them as slot values.
A secret slot is write-only: you send it once, it is stored encrypted, and a response carries hasValue: true with a null value - never the secret.
Setting one up
- Find the application, method and slots -
engini connections auth-providers sources. - Get the callback URL -
engini connections auth-providers redirect-uri --app <app>- and register it in your OAuth app with the vendor. - Create the provider with the credentials the vendor gave you.
sources. All commands and options are in the CLI reference, and the output shapes in the machine contract.
Signing in through a provider
Pass--provider - a provider name, a numeric id, or none for the connector’s own OAuth client:
--auth defaults to the provider’s own. The fields it already holds are not prompted for again.
--provider is also accepted by engini connections sign-in-url and engini connections create. Both a name and an id are looked up among the providers engini connections auth-providers usable shows you, so a provider that is disabled or not available to you is not found (exit 4).
Where the provider is pinned in the API
There are two places, and they are not the same call:- OAuth2 sign-in -
authProviderIdin the body ofPOST /v1/connections/get-sign-in-url. The server keeps it with the sign-in state, so the connection that follows is created through the same provider. - OAuth2 client-credentials methods (no sign-in) -
authProviderIdas a query parameter onPOST /v1/connections. The server ignores it for every other method.
authProviderId has three states: omitted uses the account’s default provider (when its method matches and you may use it), 0 uses the connector’s own OAuth client, and an id uses that provider. Test for “omitted” explicitly - a falsy check swallows 0.
Access control
list,getandredirect-urineed permission to manage auth providers.sourcesneeds permission to create auth providers.usable, and--provider <name|id>need only permission to use auth providers (any member when RBAC is off).usablereturns ids, names and methods - never field values.
From the SDKs
The Python SDK exposesclient.auth_providers (list, get, create, update, delete, redirect_uri, sources, usable), and the TypeScript SDK client.authProviders (the same, redirectUri in camelCase).
update, a slot you leave out keeps its stored value and "" clears it. Deleting a provider that connections are signed in through is refused with 409 AUTH_PROVIDER_IN_USE.